Independent assessors award FACT enhanced ‘Plus’ status under Cyber Essentials scheme

We’re pleased to announce that FACT has successfully renewed its Cyber Essentials Plus certification, continuing our annual independent assessment against the UK Government-backed cyber security standard. Successfully completing a second consecutive assessment demonstrates our ongoing commitment to cyber security and provides independent assurance to clients, partners and stakeholders that our systems and security controls continue to be tested and verified by external assessors.

Cyber Essentials Plus is widely recognised as one of the UK’s leading cyber security certifications. Building upon the foundation established by Cyber Essentials, the Plus certification requires independent technical verification by an accredited assessor to confirm that security controls are not only documented but are operating effectively in practice.

The importance of these controls has never been greater. Cyber security is no longer just an IT issue. It is a business issue that affects organisations of every size and sector. From ransomware and data breaches to phishing campaigns and supply chain compromises, cyber threats continue to evolve, with criminal groups increasingly operating as organised enterprises that target organisations wherever vulnerabilities exist.

Businesses do not need to be household names to become targets. Attackers often look for organisations that hold valuable information, process sensitive data, manage critical services, or form part of a larger supply chain. A successful attack can result in operational disruption, financial losses, reputational damage and, in some cases, regulatory scrutiny.

One of the most common methods used by cyber criminals remains phishing. Emails designed to impersonate trusted organisations are used to steal credentials, distribute malware and gain unauthorised access to systems. Ransomware also continues to pose a significant threat, potentially leaving organisations unable to access critical systems and data and causing significant operational disruption.

At the same time, the widespread adoption of cloud services, remote working, and mobile technology has expanded the number of potential entry points for attackers. Organisations must therefore combine appropriate technology with effective policies, processes, and user awareness to reduce risk.

Against this backdrop, Cyber Essentials and Cyber Essentials Plus have become recognised benchmarks for demonstrating good cyber security practices. Cyber Essentials focuses on five key technical controls: firewalls, secure configuration, access control, malware protection, and security update management. Together, these controls help organisations protect themselves against many of the most common cyber-attacks.

Cyber Essentials Plus builds upon these requirements through independent technical assessment, providing an additional level of assurance that an organisation’s implementation of the controls has been tested against a recognised standard.

Achieving and maintaining Cyber Essentials Plus is not simply about obtaining a certificate. The process requires organisations to review their systems, strengthen controls, address weaknesses and demonstrate an ongoing commitment to security. It encourages continual improvement and helps establish a culture where information security is considered throughout day-to-day operations.

For FACT, renewing Cyber Essentials Plus demonstrates our commitment to protecting the information entrusted to us by clients, partners and stakeholders. As an organisation that handles sensitive information and delivers specialist services, maintaining strong security controls is fundamental to the trust our clients place in us.

The annual renewal process ensures that key aspects of our cyber security arrangements continue to be scrutinised and independently tested. It demonstrates that security is not treated as a one-off exercise, but as an ongoing responsibility embedded within our operational processes.

There is also increasing recognition across both the public and private sectors that cyber security forms a key part of supplier due diligence. Many procurement exercises and contractual arrangements require organisations to demonstrate recognised security standards, and Cyber Essentials Plus provides a widely recognised mechanism for evidencing that commitment.

Most importantly, effective cyber security helps protect the continuity of services our clients rely upon. Secure systems, controlled access, robust patch management, and vigilant monitoring all contribute towards maintaining operational resilience and reducing the likelihood of disruption.

As cyber threats continue to evolve, certifications such as Cyber Essentials Plus will remain an important component of an organisation’s wider security strategy. While no certification can eliminate risk entirely, it provides an independently assessed framework for managing that risk and ensuring fundamental security controls are consistently applied.

In an increasingly digital world, demonstrating a commitment to cyber security is an essential part of maintaining trust, protecting information, and delivering confidence to clients. By renewing our Cyber Essentials Plus certification, FACT continues to demonstrate that commitment and our focus on maintaining strong, independently tested cyber security controls.

Share This Story, Choose Your Platform!

Latest
  • FACT Aces Rigorous Government Security Test

    Independent assessors award FACT enhanced ‘Plus’ status under Cyber Essentials scheme We’re pleased to announce that FACT has successfully renewed its Cyber Essentials Plus certification, continuing our annual independent assessment [...]

    Read More →
Contact FACT

Get in touch with our team.

Whether you have a specific requirement or want to understand how we can help, our specialists are ready to talk. All enquiries are handled in confidence.

FACT UK

T +44 (0) 208 891 1217

E [email protected]

A Regal House, 70 London Road, Twickenham TW1 3QS

Press